πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1004 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0ec84f54-5cb9-4788-ab78-4f744f0a4029 MEDIUM 6.1 The WP Copy Media URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… wordfence
0ebc4c47-a286-4135-90ee-eccad8579661
< 1.3.23
MEDIUM 6.1 The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result… wordfence
0e8f63e3-6392-4152-94a5-eb953d7e53fb
< 3.4.1
MEDIUM 6.1 includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS. wordfence
0e7b694f-8926-4bba-be77-42ade5d1c3b4
< 10.5
MEDIUM 6.1 The cforms2 plugin before 10.5 for WordPress has XSS. wordfence
0e7af92f-985b-4200-b147-53e98d03399b MEDIUM 6.1 The App Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5 d… wordfence
0e7825de-dc11-4471-820b-a5b189a7d61c MEDIUM 6.1 The Better Protected Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… wordfence
0e5c11dc-8326-494e-ac2c-b612c9424ff3 MEDIUM 6.1 The Uncomplicated SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and in… wordfence
0e549e4c-9f2e-40a4-9b07-7edb34bc0c9f
< 1.18.0
MEDIUM 6.1 The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd… wordfence
0e50b6a0-180b-45dd-a65b-f6b3161b068c MEDIUM 6.1 The Your Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,… wordfence
0e4f6305-d003-478e-a8ef-0b254084f56f
< 1.5
MEDIUM 6.1 The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' par… wordfence
0e4c0500-9081-446e-b34b-968c718dfce0
< 3.6
MEDIUM 6.1 The Ultimate TinyMCE plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.6 due to insufficie… wordfence
0e47daed-42cc-4d96-82a1-a3e65af9fa88
< 2.8.1
MEDIUM 6.1 The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting … wordfence
0e452c66-ac10-4960-9e99-ddd7ae3b56cf MEDIUM 6.1 The Smart Product Gallery Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
0e3adbc2-fa45-4c35-a214-2b101e8c9748
< 2.9.5
MEDIUM 6.1 The WPComplete plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in versi… wordfence
0e2e6a72-941e-4b30-b622-ed8ccfc7c504
< 6.4.1
MEDIUM 6.1 The Elessi theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 6.3… wordfence
0e27b0a8-e052-49ed-8744-a2376aa386f5 MEDIUM 6.1 The BSK Contact Form 7 Blacklist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'inserted_… wordfence
0e230f9f-5eda-4362-973b-ada9cf425697
< 1.7.6
MEDIUM 6.1 The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the … wordfence
0e227024-af7e-44f8-bed9-70d361ab590f
< 1.13.3
MEDIUM 6.1 The GlobalPayments WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, a… wordfence
0e0bee7c-8dce-421c-af16-7e5152797e6c
< 4.1.0
MEDIUM 6.1 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vu… wordfence
0e030ff8-ea9d-4b4f-8b5a-28eaa18b14de MEDIUM 6.1 The Bulk YouTube Post Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, an… wordfence
0df6f15f-308f-4397-9a67-6a6dab992568
< 5.174.1
MEDIUM 6.1 The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQ… wordfence
0df57ee1-e22c-4532-b784-408d61f4d28f
< 5.2.3
MEDIUM 6.1 The Min Max Step Quantity Limits Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri… wordfence
0de79672-f0ba-42d3-a44a-01b93801d7de MEDIUM 6.1 The CalculatorPro Calculators plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple paramete… wordfence
0ddc7488-4cc0-4e17-8c81-26cbcbe8bdae MEDIUM 6.1 The silverOrchid theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜s’ parameter in versio… wordfence
0dd2705e-d78c-4f31-b28f-1ba8b2495c80
< 3.8.0
MEDIUM 6.1 Cross-site scripting (XSS) vulnerability in go.php in the URL Cloak & Encrypt (url-cloak-encrypt) plugin < 3.8.0 for Wor… wordfence
← Prev 1001 1002 1003 1004 1005 1006 1007 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top